chore(deps): update vaultwarden/server docker tag to v1.37.4 #369

Merged
mysticalsoap merged 1 commit from renovate/vaultwarden-server-1.x into trunk 2026-10-08 14:31:11 -04:00
Collaborator

This PR contains the following updates:

Package Update Change
vaultwarden/server patch 1.37.3 → 1.37.4

Release Notes

dani-garcia/vaultwarden (vaultwarden/server)

v1.37.4

Compare Source

Security Fixes

This release contains security fixes for the following advisories. We strongly advise updating as soon as possible.

These are private for now, pending CVE assignment and publishing at a later date.

[!NOTE]
If an organization has Admins you don't fully trust, consider rotating its API key after updating (Admin Console → Settings → Rotate API key). Before this release, Admins could also view the key.

Upgrade notes

  • Reverse proxies: with IP_HEADER=X-Forwarded-For, the client IP is now the rightmost address that isn't in IP_HEADER_TRUSTED_PROXIES (it used to be the leftmost). If you have several proxies in a row, for example a CDN in front of nginx, add all of them to IP_HEADER_TRUSTED_PROXIES. Otherwise the address of the proxy in front is used for rate limiting and logs.
  • Sends: bw send receive on CLI 2026.4.2 and older no longer works, the same as against Bitwarden's own servers since v2026.8.0. Creating and managing Sends works on all clients.
  • Feature flags: these flags were removed because no client reads them anymore: ssh-agent, ssh-key-vault-item, mutual-tls, anon-addy-self-host-alias, simple-login-self-host-alias, pm-25373-windows-biometrics-v2, pm-26340-linux-biometrics-v2, desktop-ui-migration-milestone-1 to -4, cxp-import-mobile and cxp-export-mobile. If EXPERIMENTAL_CLIENT_FEATURE_FLAGS still lists one of them, startup logs a warning and saving settings in the admin panel fails until it's removed.
  • Duo: DUO_USE_IFRAME (the deprecated Traditional Prompt) is removed and ignored if set.
  • Custom templates: there's a new email template, email/recover_twofactor, sent after a login with a two-step recovery code.
  • The legacy POST /identity/accounts/register and POST /api/accounts/prelogin endpoints are removed. No current client uses them.
  • When using a MariaDB or MySQL server which does not support native TLS/SSL encrypted connections, using the Alpine image of Vaultwarden might fail to connect. Add MARIADB_TLS_DISABLE_PEER_VERIFICATION=1 as an environment variable to your Vaultwarden server environment, and it will start running again.

What's Changed

New Contributors

Full Changelog: https://github.com/dani-garcia/vaultwarden/compare/1.37.3...1.37.4

Join Discussion


This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [vaultwarden/server](https://github.com/dani-garcia/vaultwarden) | patch | `1.37.3` → `1.37.4` | --- ### Release Notes <details> <summary>dani-garcia/vaultwarden (vaultwarden/server)</summary> ### [`v1.37.4`](https://github.com/dani-garcia/vaultwarden/releases/tag/1.37.4) [Compare Source](https://github.com/dani-garcia/vaultwarden/compare/1.37.3...1.37.4) #### Security Fixes This release contains security fixes for the following advisories. We strongly advise updating as soon as possible. - Organization member revocation [\[GHSA-69q9-v8p6-xvx3\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-69q9-v8p6-xvx3) (**High**, 8.1) - Two-factor authentication [\[GHSA-7jg8-8m5x-6j9r\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-7jg8-8m5x-6j9r) (**Medium**, 6.8) - Organization invitations [\[GHSA-v576-3wvq-xh3c\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-v576-3wvq-xh3c) (**Medium**, 6.8) - Attachments [\[GHSA-q5x6-grh5-fqgc\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-q5x6-grh5-fqgc) (**Medium**, 6.5) - Organization event logs [\[GHSA-64mc-4p6f-r7x9\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-64mc-4p6f-r7x9) (**Medium**, 4.3) - Cipher sharing [\[GHSA-7ccc-c43j-4p36\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-7ccc-c43j-4p36) (**Medium**, 4.3) - Organization API key [\[GHSA-qwx4-wcv4-mpcv\]](https://github.com/dani-garcia/vaultwarden/security/advisories/GHSA-qwx4-wcv4-mpcv) (**Low**, 3.8) - Additional dependency updates and minor security enhancements These are private for now, pending CVE assignment and publishing at a later date. > \[!NOTE] > If an organization has Admins you don't fully trust, consider rotating its API key after updating (Admin Console → Settings → Rotate API key). Before this release, Admins could also view the key. #### Upgrade notes - **Reverse proxies:** with `IP_HEADER=X-Forwarded-For`, the client IP is now the rightmost address that isn't in `IP_HEADER_TRUSTED_PROXIES` (it used to be the leftmost). If you have several proxies in a row, for example a CDN in front of nginx, add all of them to `IP_HEADER_TRUSTED_PROXIES`. Otherwise the address of the proxy in front is used for rate limiting and logs. - **Sends:** `bw send receive` on CLI 2026.4.2 and older no longer works, the same as against Bitwarden's own servers since v2026.8.0. Creating and managing Sends works on all clients. - **Feature flags:** these flags were removed because no client reads them anymore: `ssh-agent`, `ssh-key-vault-item`, `mutual-tls`, `anon-addy-self-host-alias`, `simple-login-self-host-alias`, `pm-25373-windows-biometrics-v2`, `pm-26340-linux-biometrics-v2`, `desktop-ui-migration-milestone-1` to `-4`, `cxp-import-mobile` and `cxp-export-mobile`. If `EXPERIMENTAL_CLIENT_FEATURE_FLAGS` still lists one of them, startup logs a warning and saving settings in the admin panel fails until it's removed. - **Duo:** `DUO_USE_IFRAME` (the deprecated Traditional Prompt) is removed and ignored if set. - **Custom templates:** there's a new email template, `email/recover_twofactor`, sent after a login with a two-step recovery code. - The legacy `POST /identity/accounts/register` and `POST /api/accounts/prelogin` endpoints are removed. No current client uses them. - When using a MariaDB or MySQL server which does not support native TLS/SSL encrypted connections, using the Alpine image of Vaultwarden might fail to connect. Add `MARIADB_TLS_DISABLE_PEER_VERIFICATION=1` as an environment variable to your Vaultwarden server environment, and it will start running again. #### What's Changed - \[Web 2026.9.0] Support the vault banner policy by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7748](https://github.com/dani-garcia/vaultwarden/pull/7748) - Add support for basic auth response client feature flag by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7745](https://github.com/dani-garcia/vaultwarden/pull/7745) - \[web-v2026.8.1] store the user key ID by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;7693](https://github.com/dani-garcia/vaultwarden/pull/7693) - Add organizationsNew and policiesNew to sync response by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7666](https://github.com/dani-garcia/vaultwarden/pull/7666) - Add `pm-32009-new-item-types` feature flag by [@&#8203;bdd](https://github.com/bdd) in [#&#8203;7478](https://github.com/dani-garcia/vaultwarden/pull/7478) - Update Crates, GHA and JS by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7751](https://github.com/dani-garcia/vaultwarden/pull/7751) - Add `pm-34171-card-scanner` feature flag by [@&#8203;bdd](https://github.com/bdd) in [#&#8203;7477](https://github.com/dani-garcia/vaultwarden/pull/7477) - set user\_created bool for each separate invitation by [@&#8203;stefan0xC](https://github.com/stefan0xC) in [#&#8203;7753](https://github.com/dani-garcia/vaultwarden/pull/7753) - Fix revoked org members retaining access to org ciphers by [@&#8203;abhiShandy](https://github.com/abhiShandy) in [#&#8203;7554](https://github.com/dani-garcia/vaultwarden/pull/7554) - Ensure all user checked routes are confirmed by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7763](https://github.com/dani-garcia/vaultwarden/pull/7763) - Fix cortex-a53 build issues when using xx-cargo by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7774](https://github.com/dani-garcia/vaultwarden/pull/7774) - Add `undetermined-cipher-scenario-logic` feature flag (closes [#&#8203;7801](https://github.com/dani-garcia/vaultwarden/issues/7801)) by [@&#8203;cad0p](https://github.com/cad0p) in [#&#8203;7802](https://github.com/dani-garcia/vaultwarden/pull/7802) - Add Windows native credential sync to supported feature flags by [@&#8203;KingIronMan2011](https://github.com/KingIronMan2011) in [#&#8203;7798](https://github.com/dani-garcia/vaultwarden/pull/7798) - Hide the whole change-email section when EMAIL\_CHANGE\_ALLOWED is false by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7759](https://github.com/dani-garcia/vaultwarden/pull/7759) - Fix Clippy warnings across all targets by [@&#8203;tom27052006](https://github.com/tom27052006) in [#&#8203;7782](https://github.com/dani-garcia/vaultwarden/pull/7782) - Admin reset: 2fa email fallback need a verified email by [@&#8203;Timshel](https://github.com/Timshel) in [#&#8203;7770](https://github.com/dani-garcia/vaultwarden/pull/7770) - Sends cleanup: remove legacy endpoints and align with upstream by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7806](https://github.com/dani-garcia/vaultwarden/pull/7806) - Remove legacy API endpoints and compatibility code by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7809](https://github.com/dani-garcia/vaultwarden/pull/7809) - Align API with upstream and remove unwraps by [@&#8203;dani-garcia](https://github.com/dani-garcia) in [#&#8203;7810](https://github.com/dani-garcia/vaultwarden/pull/7810) - Update crates, Rust and other dependencies by [@&#8203;BlackDex](https://github.com/BlackDex) in [#&#8203;7814](https://github.com/dani-garcia/vaultwarden/pull/7814) #### New Contributors - [@&#8203;bdd](https://github.com/bdd) made their first contribution in [#&#8203;7478](https://github.com/dani-garcia/vaultwarden/pull/7478) - [@&#8203;abhiShandy](https://github.com/abhiShandy) made their first contribution in [#&#8203;7554](https://github.com/dani-garcia/vaultwarden/pull/7554) - [@&#8203;cad0p](https://github.com/cad0p) made their first contribution in [#&#8203;7802](https://github.com/dani-garcia/vaultwarden/pull/7802) - [@&#8203;KingIronMan2011](https://github.com/KingIronMan2011) made their first contribution in [#&#8203;7798](https://github.com/dani-garcia/vaultwarden/pull/7798) **Full Changelog**: <https://github.com/dani-garcia/vaultwarden/compare/1.37.3...1.37.4> [Join Discussion](https://github.com/dani-garcia/vaultwarden/discussions/7823) </details> --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC42LjAiLCJ1cGRhdGVkSW5WZXIiOiI0NC42LjAiLCJ0YXJnZXRCcmFuY2giOiJ0cnVuayIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->
chore(deps): update vaultwarden/server docker tag to v1.37.4
All checks were successful
validate / validate (pull_request) Successful in 18s
a65411206a
mysticalsoap deleted branch renovate/vaultwarden-server-1.x 2026-10-08 14:31:12 -04:00
Sign in to join this conversation.
No description provided.